IBM Engineering Lifecycle Management 7.0.3-7.2.0 DOORS XML Exp. DoS
CVE-2026-14979 Published on July 17, 2026
IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.
Vulnerability Analysis
CVE-2026-14979 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
What is a XEE Vulnerability?
The software uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities. If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.
CVE-2026-14979 has been classified to as a XEE vulnerability or weakness.
Products Associated with CVE-2026-14979
Want to know whenever a new CVE is published for IBM Engineering Lifecycle Management? stack.watch will email you.
Affected Versions
IBM Engineering Lifecycle Management:- Version 7.0.3 ( Interim Fix 001, <= ) Interim Fix 021 is affected.
- Version 7.1.0 ( Interim Fix 001, <= ) Interim Fix 009 is affected.
- Version 7.2.0 and 7.2.0 Interim Fix 001 is affected.